logo

Detecting and Analyzing an Apache Struts Exploit with Tracee

ID: d392ccbc-0d62-58fe-ac8d-82b7b3ad61ec

STIX ID: report--d392ccbc-0d62-58fe-ac8d-82b7b3ad61ec

Feed Name: Aqua Security Blog

Threat Score
65/100

Date Published: 2022-05-18

Date Updated: 2026-04-26

...
...

The report presents a Tracee-based runtime forensic analysis of an Apache Struts 2 RCE (CVE-2017-5638) compromise: attackers executed a downloaded shell script that disabled defenses, removed competing processes, retrieved a UPX-packed cryptominer from a C2, attempted credential harvesting and SSH/Redis lateral scans, and performed actions to hide evidence; Tracee captured the exploit HTTP requests, execve events, file artifacts, network scanning behavior, and attempted kernel module loading to boost mining performance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.